CVE-2021-22569
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.29%
- CWE
- CWE-696
- Published
- 2022-01-07
- Last modified
- 2026-03-13
Affected products
- Google LLC protobuf-java
- Google LLC protobuf-kotlin
- Google LLC google-protobuf [JRuby Gem]
Weakness type
Related vulnerabilities
- CVE-2026-44108 — Firewall bypass during shutdown
- CVE-2021-31379 — Junos OS: MX Series: MPC 7/8/9/10/11 cards with MAP-E: PFE halts when an attacker sends malformed IPv4 or IPv6 traffic inside the MAP-E tunnel.
- CVE-2025-31485 — GraphQL grant on a property might be cached with different objects
- CVE-2026-40583 — UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
- CVE-2024-24853 — Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Process
- CVE-2023-33224 — SolarWinds Platform Incorrect Behavior Order Vulnerability
- CVE-2025-0150 — Zoom Workplace Apps for iOS - Incorrect Behavior Order
- CVE-2026-45033 — GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor